SC-900 Describe the capabilities of Microsoft Entra Practice Question
Which THREE of the following are features of Microsoft Entra ID Governance? (Select three.)
⚠ Common exam trap
Test-takers frequently confuse security features like MFA and SSPR (which are part of Microsoft Entra ID's core authentication and protection capabilities) with governance features, which specifically focus on access lifecycle, attestation, and privileged role management.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Access reviews
Access reviews (A) are a core Microsoft Entra ID Governance capability that lets organizations periodically recertify users' group memberships, application access, and role assignments to ensure least privilege. Privileged Identity Management (B) is included in Entra ID Governance and provides just-in-time privileged role activation, approval workflows, access reviews, and audit history for privileged access. Entitlement management (C) is also a governance feature that automates access request workflows, access packages, and lifecycle policies for internal and external users. Self-service password reset (D) is an authentication/credential-management feature, not a governance capability, and multifactor authentication (E) is an authentication method for strengthening sign-in security, so neither belongs to Entra ID Governance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Access reviews
Why this is correct
Microsoft Entra Access Reviews enable organizations to efficiently manage group memberships, access to enterprise applications, and roles. They help ensure that users only have the access they need, reducing the risk of excessive or stale permissions. These reviews can be scheduled periodically or triggered on demand, requiring reviewers (e.g., group owners, managers) to attest to continued access necessity.
- ✓
Privileged Identity Management (PIM)
Why this is correct
Microsoft Entra Privileged Identity Management (PIM) allows organizations to manage, control, and monitor access to important resources. It provides just-in-time (JIT) and time-bound access to Azure resources, Microsoft Entra roles, and other Microsoft online services. PIM helps mitigate the risks of excessive, unnecessary, or misused access permissions by requiring activation for elevated roles and providing audit trails.
- ✓
Entitlement management
Why this is correct
Microsoft Entra Entitlement Management is an identity governance feature that enables organizations to manage identity and access lifecycle at scale. It automates access request workflows, access assignments, reviews, and expiration for various resources, including groups, applications, and SharePoint sites. This feature helps ensure that users have the right access to the right resources for the right duration.
- ✗
Self-service password reset
Why it's wrong here
Self-service password reset (SSPR) is a core identity management feature within Microsoft Entra ID that allows users to reset their forgotten passwords without administrator intervention. While crucial for user productivity and reducing helpdesk calls, SSPR primarily focuses on user convenience and operational efficiency in identity lifecycle management. It is not classified as an identity governance feature, which specifically deals with managing and auditing access rights and lifecycles.
- ✗
Multifactor authentication
Why it's wrong here
Multifactor authentication (MFA) is a security mechanism that requires users to provide two or more verification factors to gain access to a resource. It significantly enhances security by adding an extra layer beyond just a password. While MFA is a critical component of Microsoft Entra security and often enforced via Conditional Access policies, it is fundamentally an authentication control, not an identity governance feature focused on managing access lifecycles, entitlements, or reviews.
Go deeper
Related to this question
Learn chapter
Entra Internet Access and Private Access
Key term
Identity
Identity is the unique set of attributes that defines a user, device, or service in a computer system, determining what they can access and do.
Key term
Audit
An audit is a systematic, independent review of IT systems, processes, and controls to verify compliance with policies, standards, and regulations.
About these practice questions
One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.